NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Social Responsibility's Strategic Benefits

December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)

Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.

Working With and Communicating to Your Board of Directors

January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)

CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.

IT's Role in Growing Mid-Market Companies

January 14, 4:00 PM - 5:00 PM ET (GMT-5)

Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Researcher Finds New Way to Hack Oracle Database

Security researcher David Litchfield has released technical details of a new type of attack that could give a hacker access to an Oracle database.

 

April 24, 2008 — IDG News Service —

Security researcher David Litchfield has released technical details of a new type of attack that could give a hacker access to an Oracle database.

Called a lateral SQL injection, the attack could be used to gain database administrator privileges on an Oracle server in order to change or delete data or even install software, Litchfield said in an interview on Thursday.

Litchfield first disclosed this type of attack at the Black Hat Washington conference last February, but on Thursday he published a paper with technical details.

In a SQL injection, attackers create specially crafted search terms that trick the database into running SQL commands. Previously, security experts thought that SQL injections would only work if the attacker was inputting character strings into the database, but Litchfield has shown that the attack can work using new types of data, known as date and number data types.

Litchfield's attack targets the Procedural Language/SQL programming language used by Oracle developers.

A noted database hacker, Litchfield is best known as the researcher who published details on the bug used in the 2003 SQL Slammer worm, which targeted Microsoft's SQL Server database.

Litchfield wasn't sure how widespread lateral SQL injection vulnerabilities are, but he thinks the attack could cause real damage in some scenarios.

"If you happen to be using Oracle and you write your own applications on it, then yes, you could be writing vulnerable code," he said. "The sky is not falling ... but it's certainly something that people should be made aware of."

Database programmers should review their code to be sure it is checking to make sure that all of the data it is processing is legitimate, and not injected SQL commands, he said.

Oracle did not return a call seeking comment.

Copyright © 2008 IDG News Service. All rights reserved. IDG News Service is a trademark of International Data Group, Inc.
Loading...
 
 
IT Jobs
 
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

The Business of Managing Content: Xythos Document Management & Microsoft SharePoint

White Paper: Efficient Desktop Application Management

Operational Excellence Is Key to Maximizing IT Investments

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Effectively Managing High-Performing, Business-Critical Web Applications

Managing Service Level Agreements to Achieve Business Goals

APM Solutions: A Window into Complex Web Applications

APM Solutions Offer Insight into Complex Web Applications

Explore the value of bringing better BI to business users through dashboards.

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Grassroots Data Governance with SAP MDM

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

File Integrity Monitoring: Prove compliance and secure your IT environments

Affordable technology-no compromise. HP server solutions

SOA Educational Library at the TIBCO SOA Resource Center

CIO Viewpoints: Migrating to Exchange 2007

Thrive during global disruption. Cisco video featuring Juan Enriquez

A new level of interoperability. Make IT Work As One@novell.com

Protect data-HP All-in-One and Disk-Based systems

Businesses Transform with VMware Virtualization

Download the free CIO Starter Kit to access useful resources created by top CIOs

Virtualization Benchmark and TCO Analysis-Read Now

White Paper: Scaling Down HPC for Smaller Organizations

White Paper: Never Enough Compute Power?

Leveraging Social Computing Technologies for ERP Applications

A CISO's Guide to Application Security

Learning from BPM Leaders

State of the Market: Application Performance Management

Proactively Identify and Resolve Performance Issues

Union Bank of California Improves its Online Banking Services

The Link Between APM and Customer Satisfaction

Providing Around-the-Clock Customer Satisfaction

Gap Analysis: The Case for Data Services

Learn how Technology Escrow provides access to critical application source code

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

Renowned Engineering Institution Chooses AMD Processor-Based Servers

Corral, configure and control all your mischievous machinery with a Lantronix device server

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

Predict the future with HP Insight Power Manager

Log onto Hitachi True Stories, films inspired by the next great achievement

Earn PROFESSIONAL DOCTORATE Part-Time, Online at Syracuse University's iSchool

Make IT Work As One@novell.com

Predict the future with HP Insight Power Manager

HP LaserJet P4014n printer starting at $799 after $100 IS. www.hp.com

CIO Starter Kit includes useful resources created by top CIOs. Free Download>>

How to Start a PMO & Realize the Benefits Fast

Server Virtualization Benchmark Results

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies